URLhaus Database

You are currently viewing the URLhaus database entry for http://gtech.thngo58.com/wp-includes/9zo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:702105
URL: http://gtech.thngo58.com/wp-includes/9zo/
URL Status:Offline
Host: gtech.thngo58.com
Date added:2020-10-16 13:38:08 UTC
Last online:2020-10-18 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 13:40:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:2 days, 4 hours, 18 minutes Poor (down since 2020-10-18 17:58:06 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-18THQkEoOOOpX1u.exeexe a700963dc975d1d4b06b708a7b52b8fef542d54ef9eb715694900ac83c55ba6fVirustotal results 32.39% Heodo
2020-10-18F9cuYYgACkVmuq6Fs6B.exeexe ca7b309c6b487ee060fcaa8cc0cffd5530802829e0170271cf1e89cadb4171a1Virustotal results 32.39% Heodo
2020-10-18yJTqIqXj2lf.exeexe 8744e8d37a3854495caf9401c7c913b8d4158fa76b7269897d14222f2b9461fen/a Heodo
2020-10-18rESkFmQuNPrmNsWvYt2.exeexe a48dae1251d01afbf524a26e441f4b1e5fbd93287ac953a6dc186c78d64ebc25Virustotal results 32.86% Heodo
2020-10-18zaa.exeexe 53152795732eaa9b35b66c50702c48db59aed9dd06fce623ed2398a8db2a6ec0Virustotal results 30.43% Heodo
2020-10-18PwchRPG9t7js3yVjjV.exeexe 19d24f1f834ad26c8c156623f1b70c468ba5ed496b7ba793e01aacd63c92348dVirustotal results 25.37% Heodo
2020-10-18hwK1jkmMXG84.exeexe 4aa401fab2a01cc6525ffb9897bfa8c26acc85589fed6f512d299256ab619888n/a Heodo
2020-10-180EG2ACRRHm3ltE6cFo.exeexe 8716bb780b864ff855afbd080f92eab906f86b1b65ec594f98e48a7690818b79n/a Heodo
2020-10-18aXhYdqpukwMxZIgKkaP6.exeexe 3e63d2176bc536db0256120a8be150833877df65703893c0b13ef0290e0f7eecVirustotal results 32.86% Heodo
2020-10-18jMlNPMP7odNk.exeexe a16a1a4058fb8f6e24d31dc25283405ef100ea6d9f587f21e368638fd6b61a6cVirustotal results 29.58% Heodo
2020-10-18aTK6.exeexe ca91801e1ca6ff004ab78cfa09843c1585f8c2a88b9c96c701f347d91b755adcVirustotal results 29.58% Heodo
2020-10-18z5bQwn2rQ4aJONHXtxICb.exeexe d64be682783b24ec93cb46cbcdf336b72338a8fcbf9d706b5a9c754657162e19n/a Heodo
2020-10-17Q2YxZcWWcwiC6Uo.exeexe 432c896d9630aff3759131155dc82bd2cedb96f02659362f9019db3e4c8c4507Virustotal results 27.14% Heodo
2020-10-17Pn3Oxh9gzBsZG.exeexe 2b54e8503a7599107f6a0ffcdb1fcb1758e556cdb1b8efcc3fe410c63b6e23f8Virustotal results 22.54% Heodo
2020-10-17axQTSexmSYDhkVd7L.exeexe cda8cc151d2070db93d639c9992c23a50edd1ce6fe703a70d49f648f379e114fn/a Heodo
2020-10-17wb0YYhD5Vhj1sPP.exeexe 6243e192828d1834b8d283db1ed274e2d4fa811752a70c138e3192823e461f01Virustotal results 12.68% Heodo
2020-10-17g3nUs9LQVkRPfbSleOV1J.exeexe 45bce71a5461fe2b0a946dff505b6dced1e50b8ae9efc2cbcd3db614e708e702Virustotal results 11.27% Heodo
2020-10-17JPGD2ZkbiF0zpl.exeexe e4a97e300f6ffab4d36cf07a7a8e83b86205b1d6830e669a5359241ae44c5d41Virustotal results 10.00% Heodo
2020-10-17l7ogl7fbA9.exeexe 641caa8c21c8ad05fcfe4546178b5b518bcefa0aa145f4d47879dec5c5cfe257n/a Heodo
2020-10-178TdgZRuukBj.exeexe 0b06f2edc78ff6293d6a98c017ee9ac1f769aa9daf88e080e4ee8d6e00b5af7dVirustotal results 8.45% Heodo
2020-10-17TihReV0EI.exeexe 2977cf7fae0606b0a2ebe3f2f9cb04c5b8b65c8e143c9e6a804840fb58c11096n/a Heodo
2020-10-17eyc9FDIOpL3GYj0m9aiG.exeexe a41fffd53343bf552768508bee08ab648243172de068dab5abe41b6f21b68d9bVirustotal results 23.94% Heodo
2020-10-17ryxeDcFQtsv.exeexe 4473333a8255eec05ac59c7a2b8d9f432644726adf02ceaae0f430a4d7586555n/a Heodo
2020-10-17FT0.exeexe 34b279c6bb7a81a149a0c97f1b5d16d9eeb2f829f58dfa7d8d04e2cf14a2a76cn/a Heodo
2020-10-17B0K0JQcxOGICMNPrbBuw.exeexe 79320eeb1bb6be10d1c14776fb5c213087c1229f8d20198ccd409b2461cc00abVirustotal results 18.31% Heodo
2020-10-16cUAYBwJ64yerDbnXJhG.exeexe 3e000d000ad4d29e718bc2cadb540bc7b813d5a05340588c93bf84d7f2fa9043n/a Heodo
2020-10-163snDRBVzP.exeexe 04ea80d26ab094b4170145bb8b8b360109f68c7829f7e4ed29dda4b2196495bbVirustotal results 14.29% Heodo
2020-10-16RU3qV4XQV.exeexe 38fb0edf77027b8f006133b909783c983e43510928642fb9f15b13adb53c28efn/a Heodo
2020-10-16VTKou4i3IB33n48aPwx.exeexe 1bcfc5c7b65c29d5c48f762a1ff5236870f4661bab6260dd89f076d59a075afeVirustotal results 26.76% Heodo
2020-10-167AaMw10gKeoxqVkQ.exeexe 8cd47e6eaba86c32b77a59d6b997d8d0048a832c104372d8641e6d6cf7aa5f60n/a Heodo
2020-10-16ERuAik.exeexe 6e0519ec7aa885c224e21dc0f97052ca69f9d421863f564cefde82955e7379d1n/a Heodo